Introducing the Aur0ra Ransomware Group

BHIS ActiveSOC investigated an Aur0ra ransomware intrusion that began with vishing after aggressive email bombing, then escalated into custom C2 activity and noisy lateral movement. The attackers used Xray-core disguised as ChromeUpdate.exe and ConnectivityHost.exe, while the locker encrypted files in place and dropped the !!!README!!!DO_NOT_DELETE.txt ransom note. #Aur0ra #Xray-core #ChromeUpdate.exe #ConnectivityHost.exe #README_DO_NOT_DELETE.txt

Read More
77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets

A forum user calling themselves GordonFreeman claims to have breached the Junta Central Electoral and advertised 7,141,313 Dominican citizen records with 5,758,124 identity card photographs. The alleged dump includes cédula numbers, personal details, and JPEG portraits, but the claim remains unverified and no price was stated. #JuntaCentralElectoral #GordonFreeman #DominicanRepublic…

Read More
77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets

A forum user known as 0xSec claims to have published three XLSX user tables from docurba.beta.gouv.fr, exposing 5,152 rows of French planning officials’ names, contact details, job titles, and authority data. The alleged leak also includes administrator and staff flags, verification status, and login indicators, but the claim remains unverified. #docurba.beta.gouv.fr…

Read More
77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets

A forum user posting as 0xSec claimed to share the database of metabase.dipeeo.fr, a French GDPR compliance provider serving organisations with outsourced Data Protection Officer services and compliance software. The release reportedly contains eleven JSON collections with client, legal officer, user, subcontractor, and processing records, but the claim remains unverified and…

Read More
77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets

Sotheby’s International is investigating a cybersecurity incident involving unauthorized access to data stored on a third-party software platform. Potentially exposed information includes names, addresses, email addresses, and phone numbers, while email exchanges, property-related documentation, and financial transaction data were not accessed. #SothebysInternational #Sothebys.com

Read More
Exposed Git Repositories Leak Critical Cloud Secrets

Researchers found over 28,000 publicly exposed Git repositories across 3.5 million active web servers, revealing live AWS keys, Stripe secrets, GitHub tokens, and sensitive internal records. The exposure was caused by misconfigured public .git directories, putting organizations at risk of cloud takeover, financial data theft, and access to internal systems. #IntruderResearch…

Read More